inbound-triage

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were identified during the analysis of the skill's instructions, scripts, and reference documents.
  • [DATA_EXPOSURE]: No hardcoded secrets, credentials, or sensitive file paths were detected. The skill focuses on business process design and metadata management.
  • [COMMAND_EXECUTION]: The provided Python script (scripts/check-output.py) is a benign utility that validates the length and keyword presence in generated deliverables using standard libraries. It does not perform any dangerous shell executions or network operations.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute code from external or untrusted sources. All URLs are informational.
  • [OBFUSCATION]: No obfuscated strings, hidden URLs, or steganographic patterns were found. Content is in plain, readable text.
  • [INDIRECT_PROMPT_INJECTION]: While the skill describes workflows that ingest user form data, the skill itself is used for designing these workflows and does not expose the agent to runtime injection vulnerabilities via executable capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:46 PM
Security Audit — agent-trust-hub — inbound-triage